Ceri Coburn

Principal Security Consultant at NetSPI

Bridgend, Wales, United Kingdom
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts

Summary

🤩
Rockstar
Ceri Coburn is a Principal Security Consultant with 19 years of hands-on experience in offensive security, reverse engineering, and exploit development. Based in Bridgend, Wales, she builds and analyzes malware for defensive research, specializes in privilege escalation and beacon detection, and has contributed notable tooling like enhancements to BeaconEye, SweetPotato, and Rubeus. Her work bridges deep Windows internals and practical red team operations, routinely turning obscure bugs into reliable exploits and bypasses. Ceri regularly presents at top security conferences, translating low-level technical findings into actionable insights for defenders. Formerly a CTO and VP of Applications, she combines leadership experience with persistent curiosity—she’ll reverse-engineer a binary just to see what secrets it hides.
code19 years of coding experience
job9 years of employment as a software developer
languagesEnglish, Welsh
github-logo-circle

Github Skills (25)

privilege-escalation10
kerberos10
security10
security-testing10
exploit10
cryptography10
dotnet-core10
reverse-engineering10
csharp10
security-scan10
windows-nt10
it-security9
rpc9
smartcard9
fileio9

Programming languages (12)

C#PowerShellTypeScriptJavaJinjaC++CJavaScript

Github contributions (5)

github-logo-circle
CCob/SweetPotato

Apr 2020 - May 2022

Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019
Role in this project:
userSecurity Engineer
Contributions:1 review, 21 commits, 4 PRs in 2 years 1 month
Contributions summary:Ceri focused on developing and enhancing the "SweetPotato" tool, a local service to SYSTEM privilege escalation exploit for Windows. Their contributions included implementing support for launching beacon processes and adding additional failure logic within the framework. They also improved server detection, added support for the ncacn_np transport, and incorporated initial functionality related to print spooler privilege escalation. These modifications demonstrate a deep understanding of Windows internals and exploit development techniques.
windows-serverwindowswindows-7privilegepefile
CCob/BeaconEye

Aug 2021 - Sep 2021

Hunts out CobaltStrike beacons and logs operator command output
Role in this project:
userBack-end Developer & Security Engineer
Contributions:3 releases, 22 commits, 1 PR in 29 days
Contributions summary:Ceri primarily focused on developing and improving the `BeaconEye` project, which is designed to detect and analyze CobaltStrike beacons. Their contributions include adding project files, fixing screenshot callback handling, and improving speed by scanning the process heap only. They also added initial support for 32-bit and 64-bit minidump scanning functionality, demonstrating a focus on reverse engineering and security analysis.
operatorlogginglogsbeaconscobaltstrike
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.
Request Free Trial